A security consulting firm audits a new software application…

A security consulting firm audits a new software application that uses proprietary encryption algorithms to secure data, but the algorithms have not verified to be secure yet because they are not open for review. What model should the security consultants recommend to the application developer to follow for best practices on using encryption models that are proven to be secure?